1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

unwanted link

Discussion in 'Internet Explorer & Microsoft Edge' started by davee, 2004/05/10.

Thread Status:
Not open for further replies.
  1. 2004/05/10
    davee

    davee Inactive Thread Starter

    Joined:
    2002/10/16
    Messages:
    130
    Likes Received:
    0
    Hi there
    a small problem i have is that when I click on the search button on my internet explorer & try to customize it i get a link to a web site i don't want how can i fix this ? :eek: cheers davee !
     
  2. 2004/05/10
    Miz

    Miz Inactive Alumni

    Joined:
    2002/05/02
    Messages:
    2,345
    Likes Received:
    35
    Have a read of this page for information on spyware and how to remove it.

    If you're still having problems after installing, updating and scanning with Ad-Aware and Spybot (links to the downloads on the above page), post a Hijack This log back here for more help.
     
    Miz,
    #2

  3. to hide this advert.

  4. 2004/05/11
    davee

    davee Inactive Thread Starter

    Joined:
    2002/10/16
    Messages:
    130
    Likes Received:
    0
    Hi there : thanks for your quick reply . I have ran ad-aware,spybot , clever cleaner ,& cw shredder these are what i have installed . but the link still appears when i try to customize. so i will post the log from "hijack this "
    Logfile of HijackThis v1.97.7
    Scan saved at 5:25:37 PM, on 11/05/04
    Platform: Windows 98 Gold (Win9x 4.10.1998)
    MSIE: Internet Explorer v5.00 (5.00.2919.6304)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\PROGRAM FILES\AGNITUM\OUTPOST FIREWALL 1.0\OUTPOST.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE
    C:\CSAFE\AUTOCHK.EXE
    C:\IBMTOOLS\APTEZBTN\APTEZBP.EXE
    C:\PROGRAM FILES\MOUSE DRIVER\MOUSE DRIVER\3.5\MOUSE32A.EXE
    C:\WINDOWS\SYSTEM\QTTASK.EXE
    C:\MOPYFISH\GETPOINT.EXE
    C:\IBMTOOLS\APTEZBTN\RAKUSB.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    A:\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.sex-family.net/sherbook/search/search.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.bbc.co.uk/sport1/hi/football/teams/e/everton/default.stm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.sex-family.net/sherbook/search/search.html
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
    O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NAVAPW32.EXE /LOADQUIET
    O4 - HKLM\..\Run: [Outpost Firewall] C:\PROGRAM FILES\AGNITUM\OUTPOST FIREWALL 1.0\outpost.exe /waitservice
    O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
    O4 - HKLM\..\Run: [ConfigSafe] C:\CSAFE\AUTOCHK.EXE
    O4 - HKLM\..\Run: [AEZBProc] c:\ibmtools\aptezbtn\aptezbp.exe
    O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Mouse Driver\Mouse Driver\3.5\MOUSE32A.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
    O4 - HKLM\..\RunServices: [Outpost Firewall] C:\PROGRAM FILES\AGNITUM\OUTPOST FIREWALL 1.0\outpost.exe /service
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - Startup: Mopy Points Collector.lnk = C:\MOPYFISH\GETPOINT.EXE
    O12 - Plugin for .bcf: C:\PROGRA~1\INTERN~1\Plugins\NPBelv32.dll
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://fpdownload.macromedia.com/pub/shockwave/cabs/director/swdir.cab
    O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security1.norton.com/sa/common/common/bin/cabsa.cab
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - http://www.pcpitstop.com/mhLbl.cab
    O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://www.pcpitstop.com/internet/pcpConnCheck.cab
    O16 - DPF: {78960E0E-0B0C-11D4-8997-00104BD12D94} (AV Class) - http://www.pcpitstop.com/antivirus/PCPAV.CAB
    O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - https://www-3.ibm.com/pc/support/access/sdccommon/download/IbmEgath.cab
    O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
    O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potc_x.cab
    O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/games/clients/y/jt0_x.cab
    O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
    O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?38115.8635069444

    cheers davee.
     
  5. 2004/05/11
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    Downoad the search fix below, dont use it yet

    Start Hijackthis and place a check next to these items
    Close all browser windows and shut down all other programs(even Folders) that show in the taskbar. Then Hit fix selected
    [items in blue are recommended or optional]

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.sex-family.net/sherbook/search/search.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.sex-family.net/sherbook/search/search.html


    Optional>>O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
    =======

    This is OS independant. meaning it will work on any windows and IE version
    Download this, then double click(while IE is still closed)
    http://www.spywareinfo.com/downloads/tools/IEFIX.reg
    and answer yes when asked to have its contents added to the Registry.
    then you can delete it.

    Reboot to let things sink in
     
  6. 2004/05/11
    davee

    davee Inactive Thread Starter

    Joined:
    2002/10/16
    Messages:
    130
    Likes Received:
    0
    Hi there Lonny , did what you suggested and would you believe it
    I'm all fixed A BIG THANKS (but it did give me a bit of a scare ,cause when i went to log back on my home page , was , I quote , 'about blank ' so nothing came up , I had to reset my home page through tools internet options )So anyway everthing's o'kay thanks again
    cheer's davee :D
     
  7. 2004/05/11
    Johanna

    Johanna Inactive Alumni

    Joined:
    2003/03/08
    Messages:
    2,402
    Likes Received:
    2
    Davee,
    Go to the Security Forum and read the sticky posted at the top about Hijacking, just so you don't get annoyed with a similar problem again. Also, Spybot has an "immunize" feature on it, and near it is a setting to lock the IE browser. You might want to read up on those two features, and see if they will help you.

    Having your browser Hijacked is like coming home and finding some guy you don't know, laying on the couch watching tv... it's an invasion of space and privacy. Glad you got it fixed.

    Johanna
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.